Chowdhury Rahman
Interim CISO - Global Combat Air Programme @Leonardo
Signup · Get unlimited contacts
WORK HISTORY
Interim CISO - Global Combat Air Programme @Leonardo
Acting CISO for GCAP. Leadership and SQEP across- Risk Management across FCA, GCAP, Edgewing, G2E, K4- MoD Secure by Design (SbD)- Supply Chain Assurance for the programme and wider organisation- Providing strategic directions and Security Architecture expertise across ISANKE @ ICS domain in National and Tri-Lat forums- SME advisory at mutiple SWGs on procurement, supply chain, critical assets, OT, product security- Board level, C-level engagements across national and international partners for strategic security alignment.
EDUCATION
BRAC University
BSc, Computer Science
University of Surrey
MSc, Management Information Systems
SKILLS
ABOUT CHOWDHURY RAHMAN
Experienced cybersecurity executive with a can-do attitude and an inquisitive mindset with over 16 years of proven expertise in shaping and executing strategic cybersecurity programs for multi-billion-dollar, multi-national defence and public sector initiatives, including Global Combat Air Programme (GCAP) and National Policing Digital Strategy 2030. Experienced in engaging with C-level stakeholders at enterprise boards, law enforcement agencies, and global clients to deliver strategic security outcomes. Adept at building high-performing security teams, mentoring SMEs, and fostering a culture of continuous improvement and zero-blame incident response.Worked closely with Police Digital Service National CISO and Chief Cyber Architect on multiple workstreams that includes creating Security Policy Framework, Principles and Policies for National Policing with a view to implementing nationally across all forces; Identity and Access management strategy and recommendation for Police Digital Service and National Policing, and designing and implementing a new Management Reporting Dashboard for the Cyber Services team within PDS. Designing and assessing these solutions using sound security architecture principles across PDS and National Policing environments, ensuring information systems are compliant with frameworks (e.g, NIST, ISO27001, CIS and OWASP), applicable laws, policies and procedures.Previously responsible for the overall cyber security, threat intelligence, governance, risk and compliance assurance of the platforms, working with members of DevOps, Infrastructure and Engineering teams globally. Leading post-acquisition merger of different teams across different geographic locations from security and compliance perspective by conducting risk assessment on new platform, setting up milestones to reach required compliance level in line with ISO 27001:2013 controls and for surveillance audits. Led the organization through the ISO27001:2013 recertification cycle with zero findings. Solid understanding of SOC2, ISO27001 standards by guiding through the accreditation, re-certification process and surveillance audits. Also experienced in Data Protection Act (DPA)/ GDPR compliance along with OWASP top 10, COBIT5, NIST 800, SANS top 20, CIS benchmarks, Cloud Security Alliance CCM v3.0.1, ITILv3. As the SME have dealt with RFP processes for over 250 international clients and due diligence processes. Also I have experience with various international regulatory laws such as US-EU privacy shield, GDPR, CCPA, SOX, MIFID II, HIPAA, PIPEDA, PDPA.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.